{"api_version":"1","generated_at":"2026-07-23T11:33:02+00:00","cve":"CVE-2006-4193","urls":{"html":"https://cve.report/CVE-2006-4193","api":"https://cve.report/api/cve/CVE-2006-4193.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4193","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4193"},"summary":{"title":"CVE-2006-4193","description":"Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-17 01:04:00","updated_at":"2021-07-23 12:55:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=8","name":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=8","refsource":"MISC","tags":["Exploit","Vendor Advisory"],"title":"XSec => [XSec-06-02]: Internet Explorer (IMSKDIC.DLL) COM Object Instantiation Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=9","name":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=9","refsource":"MISC","tags":["Exploit","Vendor Advisory"],"title":"XSec => [XSec-06-03]: Internet Explorer (CHTSKDIC.DLL) COM Object Instantiation Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19521","name":"19521","refsource":"BID","tags":["Exploit"],"title":"Microsoft Internet Explorer IMSKDIC.DLL Denial Of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/29347","name":"29347","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28439","name":"ie-msoe-dos(28439)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19529","name":"19529","refsource":"BID","tags":["Exploit"],"title":"Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/29345","name":"29345","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28438","name":"ie-chtskdic-dos(28438)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/443295/100/0/threaded","name":"20060815 [XSec-06-03]: Internet Explorer (CHTSKDIC.DLL) COM Object Instantiation Vulnerability","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/29346","name":"29346","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/443299/100/0/threaded","name":"20060815 [XSec-06-04]: Internet Explorer (msoe.dll) COM Object Instantiation Vulnerability","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1402","name":"1402","refsource":"SREASON","tags":[],"title":"SecurityReason - Internet Explorer (msoe.dll) COM Object Instantiation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/443290/100/0/threaded","name":"20060815 [XSec-06-02]: Internet Explorer (IMSKDIC.DLL) COM Object Instantiation Vulnerability","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=10","name":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=10","refsource":"MISC","tags":["Exploit","Vendor Advisory"],"title":"XSec => [XSec-06-04]: Internet Explorer (msoe.dll) COM Object Instantiation Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28436","name":"ie-imskdic-dos(28436)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19530","name":"19530","refsource":"BID","tags":["Exploit"],"title":"Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4193","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4193","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4193","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ie-msoe-dos(28439)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28439"},{"name":"29347","refsource":"OSVDB","url":"http://www.osvdb.org/29347"},{"name":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=8","refsource":"MISC","url":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=8"},{"name":"29345","refsource":"OSVDB","url":"http://www.osvdb.org/29345"},{"name":"20060815 [XSec-06-03]: Internet Explorer (CHTSKDIC.DLL) COM Object Instantiation Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/443295/100/0/threaded"},{"name":"1402","refsource":"SREASON","url":"http://securityreason.com/securityalert/1402"},{"name":"19530","refsource":"BID","url":"http://www.securityfocus.com/bid/19530"},{"name":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=10","refsource":"MISC","url":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=10"},{"name":"20060815 [XSec-06-02]: Internet Explorer (IMSKDIC.DLL) COM Object Instantiation Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/443290/100/0/threaded"},{"name":"19521","refsource":"BID","url":"http://www.securityfocus.com/bid/19521"},{"name":"ie-imskdic-dos(28436)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28436"},{"name":"19529","refsource":"BID","url":"http://www.securityfocus.com/bid/19529"},{"name":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=9","refsource":"MISC","url":"http://www.xsec.org/index.php?module=releases&act=view&type=1&id=9"},{"name":"29346","refsource":"OSVDB","url":"http://www.osvdb.org/29346"},{"name":"20060815 [XSec-06-04]: Internet Explorer (msoe.dll) COM Object Instantiation Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/443299/100/0/threaded"},{"name":"ie-chtskdic-dos(28438)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28438"}]}},"nvd":{"publishedDate":"2006-08-17 01:04:00","lastModifiedDate":"2021-07-23 12:55:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4193","Ordinal":"19519","Title":"CVE-2006-4193","CVE":"CVE-2006-4193","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4193","Ordinal":"1","NoteData":"Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4193","Ordinal":"2","NoteData":"2006-08-16","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4193","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}